File name Malware name
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{794885C C-5EB7-46E3-A937-AD890A6C6677}\InprocServer32, Apartment Registry item
HKEY_LOCAL_MACHINE\Software\Classes\Interface\{000 20A01-0000-0000-C000-000000000046}\ProxyStubClsid32, {00020420-0000-0000-C000-000000000046} Registry item
HKEY_LOCAL_MACHINE\Software\Classes\Interface\{897 8B0BE-A89E-3FF9-9834-77862CEBFF3D}\TypeLib, {BED7F4EA-1A96-11D2-8F08-00A0C9A6186D} Registry item
HKEY_LOCAL_MACHINE\Software\Classes\Record\{8ABD8C B3-A365-32F9-9914-F08EC1FEC4CA}\2.0.0.0, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089 Registry item
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\Installer\UserData\S-1-5-18\Components\3FCDF7AB373EA1D4ABFE8F309A00FA29, Registry item
C:\Documents and Settings\All Users\Документы\limeby._dl BackWebLite
C:\Documents and Settings\All Users\Application Data\kemucumybe.dll A-Trojan 2.0
C:\Documents and Settings\All Users\Документы\vomocyta.vbs Adware.IpWins
C:\WINDOWS\system32\lezug.bat Adware.IpWins
C:\Documents and Settings\Администратор\Cookies\yhanilen._dl A-Trojan 2.0
C:\WINDOWS\system32\ytujehug.bin BackWebLite
C:\Program Files\Common Files\uvulavafo.inf BackWebLite
C:\Documents and Settings\Администратор\Local Settings\Temporary Internet Files\novojatok.reg Adlogix
C:\Documents and Settings\Администратор\Local Settings\Temporary Internet Files\rika._dl AceBot
C:\WINDOWS\luwalafom.bin NavExcel
C:\Documents and Settings\Администратор\Application Data\qageneso._dl BackWebLite
C:\Documents and Settings\All Users\Application Data\sopopyk.inf BackWebLite
C:\WINDOWS\system32\azec._sy BackWebLite
C:\Documents and Settings\All Users\Application Data\ugon.ban AceBot
C:\Documents and Settings\Администратор\Cookies\ibuxu.inf Adware.IpWins
C:\Documents and Settings\Администратор\Cookies\lupejyvo.com Adware.IpWins
C:\Documents and Settings\Администратор\Local Settings\Application Data\xumicegu.dll BackWebLite
C:\Documents and Settings\All Users\Application Data\dohes.inf A-Trojan 2.0
C:\Program Files\Common Files\usymiwos.sys Adware.IpWins
C:\Documents and Settings\All Users\Документы\egufonu.scr Adlogix
C:\Documents and Settings\All Users\Application Data\hinetuzyr.dat Adlogix
C:\Program Files\Common Files\ilugu.bat MPower
C:\Program Files\Common Files\sigypefely.inf Adlogix
C:\WINDOWS\system32\isydomopo.reg Advware.Adstart.b
C:\Program Files\Common Files\udypyratal.sys Advware.Adstart.b
C:\WINDOWS\vybukawar._dl MPower
C:\Documents and Settings\Администратор\Cookies\omok.dl PopMonster Description
C:\Documents and Settings\All Users\Application Data\ypekoqi.bat PopMonster Description
C:\Documents and Settings\Администратор\Cookies\ykyb._sy PerMedia